CVE-2020-1695
Summary
| CVE | CVE-2020-1695 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-05-19 15:15:00 UTC |
| Updated | 2023-11-07 03:19:00 UTC |
| Description | A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 32 | All | All | All |
| Operating System | Fedoraproject | Fedora | 33 | All | All | All |
| Application | Redhat | Resteasy | All | All | All | All |
| Application | Redhat | Resteasy | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 32 Update: resteasy-3.0.26-6.fc32 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| 1730462 – (CVE-2020-1695) CVE-2020-1695 resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class | CONFIRM | bugzilla.redhat.com | Issue Tracking, Vendor Advisory |
| [SECURITY] Fedora 33 Update: resteasy-3.0.26-6.fc33 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 32 Update: resteasy-3.0.26-6.fc32 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 33 Update: resteasy-3.0.26-6.fc33 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159457 Oracle Enterprise Linux Security Update for pki-core:10.6 and pki-deps:10.6 (ELSA-2021-1775)
- 239305 Red Hat Update for pki-core:10.6 and pki-deps:10.6 (RHSA-2021:1775)
- 940288 AlmaLinux Security Update for pki-core:10.6 and pki-deps:10.6 (ALSA-2021:1775)
- 960379 Rocky Linux Security Update for pki-core:10.6 and pki-deps:10.6 (RLSA-2021:1775)